Your Amóni account can reboot servers, reinstall them and change who has access, so the password alone should not be enough to get in. Two-factor authentication adds a six-digit code from an app on your phone at every sign-in. It takes two minutes to set up. Do it before the account has anything on it worth protecting, which is sooner than most people think.
What you need
An authenticator app on your phone: Google Authenticator, Microsoft Authenticator, Authy, 1Password, Bitwarden or any other app that speaks the TOTP standard. Nothing else. We do not send codes by SMS.
Turn it on
- Open Account in the sidebar and click the Security tab. The Two-Factor Authentication box shows Disabled.
- Click Enable 2FA. A QR code appears, with the secret printed next to it for apps that cannot scan.
- In your authenticator app, add an account and scan the code. The app starts showing a six-digit number that changes every 30 seconds.
- Type the current number into the Enter the 6-digit code to confirm field and click Enable 2FA. This proves the app is set up correctly before we start asking for codes.
- Eight recovery codes appear. They are shown once. Copy them somewhere safe now; the next section explains why.



Keep the recovery codes
A recovery code signs you in when the phone is gone: lost, wiped, replaced, or in a drawer at home while you are at the datacenter. Each code works once. Store them where you keep other secrets, a password manager entry or a printed sheet in a safe place, and not in a note on the phone that carries the authenticator. If you use them up, disable and re-enable two-factor authentication to get a fresh set.
What signing in looks like now
After the password, the sign-in page asks for the code from your app. A recovery code works in the same field. That is all: no extra step on pages inside the portal, and API keys are not affected because they never sign in.

Separately from this, a sign-in from a browser we have not seen before may ask for a code sent to your email. That check exists whether or not two-factor authentication is on. Tick Trust this device for 60 days on a computer you use regularly and it will not ask again for that period.
Turn it off, or move it to a new phone
On the Security tab click Disable 2FA. You are asked for your account password and a current code (a recovery code also works). Moving to a new phone is the same operation twice: disable with a code from the old phone or a recovery code, then enable again and scan with the new one. Do it before you hand in the old phone.
Troubleshooting
- “That code did not match.” Codes depend on the clock. Make sure the phone's time is set automatically, wait for the next code and try again. During setup, scan the QR code once more if it keeps failing; a second scan of the same code creates a duplicate entry in some apps, so delete the first.
- I lost the phone and the recovery codes. Contact support from the account's email address. After we verify who you are, we reset two-factor authentication on the account and you set it up again. This takes longer than a recovery code would have.
- A colleague needs to sign in too. Do not share your login or your codes. Link them under Account → Contacts with their own login and role; see invite your team.
- I want two-factor authentication for a script. Scripts use API keys, which are scoped and never ask for a code. Create them under Account → API Keys.
Still stuck?
Open a support ticket or email support@netrouting.com from the address on the account. If you are locked out, say so in the subject line and we prioritise it.